Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionEasy
A company is deploying a new web application to Azure App Service. The application needs to securely store connection strings, API keys, and other sensitive configuration data. The security team mandates that these secrets must be centrally managed, encrypted at rest, and accessible only by authorized Azure services. Which Azure service should be used to meet these requirements?
- AAzure Monitor
- BAzure Key Vault
- CAzure Storage Account
- DAzure SQL Database
Show answer & explanationAnswer & explanation
Correct answer: B. Azure Key Vault
Azure Key Vault is specifically designed for securely storing and managing secrets, keys, and certificates. It provides centralized management, encryption at rest, and fine-grained access control, making it the ideal solution for this scenario.
Why the other options are wrong
- A. Azure Monitor is used for collecting, analyzing, and acting on telemetry data from Azure resources, not for secret storage.
- C. Azure Storage Accounts are primarily for storing large amounts of unstructured data and are not optimized for secret management.
- D. Azure SQL Database is a relational database service and is not designed for general secret management.
Azure Key Vault
A cloud service for securely storing and accessing secrets, keys, and certificates. It helps protect cryptographic keys and other secrets used by cloud applications and services.
- Centralized secret management.
- Hardware Security Module (HSM) protected keys.
- Integration with other Azure services for secure access.
Memory trick: Keys in the Vault keep secrets safe and sound.